Gerfried Fuchs uploaded new packages for dokuwiki which fixed the
following security problems:
CVE-2010-0287
It was discovered that an internal variable is not properly sanitized
before being used to list directories. This can be exploited to list
contents of arbitrary directories.
CVE-2010-0288, Debian Bug #565406
It was discovered that the ACL Manager plugin doesn't properly check
the administrator permissions. This allow an attacker to introduce
arbitrary ACL rules and thus gaining access to a closed Wiki.
CVE-2010-0289
It was discovered that the ACL Manager plugin doesn't have protections
against cross-site request forgeries (CSRF). This can be exploited to
change the access control rules by tricking a logged in administrator
into visiting a malicious web site.
For the lenny-backports distribution the problems have been fixed in
version 0.0.20090214b-3.1~bpo50+1.
For the squeeze and sid distributions the problems have been fixed in
version 0.0.20090214b-3.1.
If you don't use pinning (see [1]) you have to update the packages
manually via "apt-get -t lenny-backports install <packagelist>" with the
packagelist of your installed packages affected by this update.
[1] <http://backports.org/dokuwiki/doku.php?id=instructions>
We recommend to pin the backports repository to 200 so that new versions
of installed backports will be installed automatically:
Package: *
Pin: release a=lenny-backports
Pin-Priority: 200
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Debian | 6 | all | dokuwiki | < 0.0.20090214b-3.1 | dokuwiki_0.0.20090214b-3.1_all.deb |